If it were a straightforward DoS, then yes, you can see where it's coming from. However, we're being hit by something called a SYN flood, which makes things a lot more difficult to trace as the attacking IP is spoofed. It's the digital equivalent of ringing someone's doorbell and running away - the server never gets the chance to identify the source.
We've been hit several times before, but the current attack is the largest we've ever experienced - we can shrug off low-level attacks without too much difficulty - and have on several occasions - but the sheer volume of this attack makes things that bit more difficult.